Mission accomplie. Voici le rapport de Combofix :
ComboFix 12-01-06.01 - Laura 06/01/2012 19:23:24.1.4 - x86
MicrosoftÆ Windows Vistaô …dition Familiale Premium 6.0.6001.1.1252.33.1036.18.3071.1894 [GMT 1:00]
LancÈ depuis: c:\users\Laura\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Un nouveau point de restauration a ÈtÈ crÈÈ
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\firefox.exe
c:\programdata\tmp195E.tmp
c:\programdata\tmpE035.tmp
c:\users\Laura\audacity-win-unicode-1.3.13.exe
c:\users\Laura\b7100MUx.exe
c:\users\Patrick\OOo_3.0.0_Win32Intel_install_wJRE_fr.exe
c:\windows\bwUnin-8.1.1.50-8876480SL.exe
c:\windows\ST6UNST.000
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\FAST2001.ocx
c:\windows\system32\tmpA073.tmp
c:\windows\system32\tmpA17D.tmp
J:\autorun.inf
.
.
((((((((((((((((((((((((((((( Fichiers crÈÈs du 2011-12-06 au 2012-01-06 ))))))))))))))))))))))))))))))))))))
.
.
2012-01-06 18:35 . 2012-01-06 18:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-06 18:35 . 2012-01-06 18:35 -------- d-----w- c:\users\Patrick\AppData\Local\temp
2012-01-06 12:14 . 2012-01-06 12:14 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{33F12E48-DF26-4536-8522-F52A77C760A9}\offreg.dll
2012-01-03 19:26 . 2012-01-03 19:26 -------- d-----w- c:\users\Laura\AppData\Roaming\Malwarebytes
2012-01-03 19:25 . 2012-01-03 19:25 -------- d-----w- c:\programdata\Malwarebytes
2012-01-03 19:25 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-02 15:47 . 2012-01-02 21:41 -------- d-----w- c:\users\Laura\AppData\Local\MigWiz
2012-01-02 09:52 . 2012-01-02 09:52 0 ---ha-w- c:\users\Laura\AppData\Local\BITE782.tmp
2012-01-02 09:52 . 2012-01-02 09:52 0 ---ha-w- c:\users\Laura\AppData\Local\BITE714.tmp
2012-01-02 09:43 . 2012-01-02 09:43 0 ---ha-w- c:\users\Laura\AppData\Local\BIT6122.tmp
2012-01-02 09:12 . 2012-01-02 09:12 0 ---ha-w- c:\users\Laura\AppData\Local\BIT580E.tmp
2012-01-02 09:09 . 2012-01-02 09:09 0 ---ha-w- c:\users\Laura\AppData\Local\BIT62C7.tmp
2012-01-02 09:05 . 2012-01-02 09:05 0 ---ha-w- c:\users\Laura\AppData\Local\BIT62E7.tmp
2012-01-02 08:41 . 2012-01-02 08:41 0 ---ha-w- c:\users\Laura\AppData\Local\BIT6079.tmp
2012-01-02 08:41 . 2012-01-02 08:41 0 ---ha-w- c:\users\Laura\AppData\Local\BIT5FEB.tmp
2012-01-02 08:19 . 2012-01-02 08:19 0 ---ha-w- c:\users\Laura\AppData\Local\BIT691E.tmp
2011-12-31 10:49 . 2011-12-31 10:49 -------- d-----w- c:\users\Laura\AppData\Roaming\Creative
2011-12-31 10:44 . 2011-12-31 10:45 -------- d-----w- c:\programdata\Creative
2011-12-31 10:44 . 2011-12-31 10:44 -------- d--h--w- c:\programdata\{26D901A1-2540-4430-81DC-0317F01BD7BE}
2011-12-31 10:44 . 2011-12-31 10:44 -------- d-----w- c:\program files\Creative
2011-12-31 10:44 . 2011-12-31 10:44 -------- d--h--w- c:\programdata\{3F99F896-A711-4F43-8412-BC4D34E35545}
2011-12-30 14:03 . 2011-12-30 14:03 -------- d-----w- c:\windows\system32\EventProviders
2011-12-28 13:04 . 2011-12-28 13:04 -------- d-----w- c:\program files\ASIO4ALL v2
2011-12-28 13:04 . 2011-12-28 13:04 -------- d-----w- c:\program files\VstPlugins
2011-12-28 13:04 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2011-12-28 13:03 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\system32\vorbis.acm
2011-12-28 13:03 . 2011-12-28 13:03 -------- d-----w- c:\program files\Outsim
2011-12-28 12:59 . 2011-12-30 13:58 -------- d-----w- c:\program files\Image-Line
2011-12-28 11:54 . 2011-12-28 11:54 -------- d-----w- c:\program files\Microsoft Silverlight
2011-12-27 12:29 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{33F12E48-DF26-4536-8522-F52A77C760A9}\mpengine.dll
2011-12-26 12:31 . 1999-12-17 09:13 86016 ----a-w- c:\windows\unvise32.exe
2011-12-26 12:31 . 2011-12-26 12:31 -------- d-----w- c:\program files\emagic
2011-12-26 12:30 . 2011-12-26 12:30 -------- d-----w- c:\program files\DigitalSoundPlanet
2011-12-26 12:23 . 2011-12-26 12:23 -------- d-----w- c:\users\Laura\AppData\Roaming\Cycling '74
2011-12-26 12:23 . 2011-12-26 12:23 -------- d-----w- c:\program files\AkaiPro
2011-12-14 18:06 . 2011-12-14 18:06 653584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-12-11 15:45 . 2011-12-28 11:50 -------- d-----w- c:\program files\Warcraft III
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-02 16:57 . 2011-12-02 16:57 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-02-14 21:00 . 2011-02-14 21:00 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ÈlÈments vides & les ÈlÈments initiaux lÈgitimes ne sont pas listÈs
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 21:45 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 2153472]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"EADM"="c:\program files\Electronic Arts\EADM\EADMUI\EADMUI.exe" [2011-03-03 11509760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-29 4911104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"OPTENET_GUI"="c:\progra~1\CONTRO~1\bin\optgui.exe" [2008-05-06 424608]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-03 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-03 13535776]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-02-14 30192]
"CarboniteSetupLite"="c:\program files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe" [2008-04-07 306112]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-06-06 64256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Malwarebytes' Anti-Malware"="d:\programmes dÈsinfection\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
c:\users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'Ècran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
Outil de notification Live Search.lnk - c:\users\Laura\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [N/A]
.
c:\users\LoÔc et Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Game Alarm.lnk - c:\games\Game Alarm\gamealarm.exe [2010-3-6 19721728]
Notification de cadeaux MSN.lnk - c:\users\Laura\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe [N/A]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
c:\users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-1-11 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-11 692224]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-8-3 63696]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-4-5 494920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\toolbar_eula_launcher]
2007-02-20 16:20 28672 ----a-w- c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3672089264-3422931028-3440631740-1001]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'T‚ches planifiÈes'
.
2012-01-06 c:\windows\Tasks\Extension de garantie-Patrick.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-06-10 10:13]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 19:33]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 19:33]
.
.
------- Examen supplÈmentaire -------
.
uStart Page = hxxp://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
mStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://
www.google.com/keyword/%s
LSP: c:\program files\Controle Parental\bin\lsp.dll
TCP: Interfaces\{2E797A3A-6B6A-44F0-8407-2CD377AB7E79}: NameServer = 8.8.8.8,8.8.8.4
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Laura\AppData\Roaming\Mozilla\Firefox\Profiles\z3uj7mv7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DVDVideoSoft Toolbar: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - %profile%\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - (no file)
Toolbar-{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - (no file)
Toolbar-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
WebBrowser-{A8F9752D-E2B8-4E7A-86B5-499F4330E2FE} - (no file)
WebBrowser-{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-06 19:35
Windows 6.0.6001 Service Pack 1 NTFS
.
Recherche de processus cachÈs ...
.
Recherche d'ÈlÈments en dÈmarrage automatique cachÈs ...
.
Recherche de fichiers cachÈs ...
.
Scan terminÈ avec succËs
Fichiers cachÈs: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-3672089264-3422931028-3440631740-1001\Software\SecuROM\License information*]
"datasecu"=hex:c9,63,61,46,59,a8,56,f6,d9,2c,14,ca,4c,54,90,26,36,f7,e5,b1,5d,
89,e2,79,05,08,c3,1d,19,ae,ab,12,e1,4f,e9,57,b6,aa,b0,96,81,4c,4c,59,0d,ee,\
"rkeysecu"=hex:4a,b6,68,a0,83,e7,7f,a1,ee,98,d5,a1,27,85,8a,50
.
[HKEY_USERS\S-1-5-21-3672089264-3422931028-3440631740-1002\Software\SecuROM\License information*]
"datasecu"=hex:29,da,29,fc,7c,98,12,64,cf,ad,a3,c4,95,08,9b,ff,a4,90,9d,ff,ec,
db,5a,c6,b9,d6,8a,65,30,a0,97,62,fb,cd,34,67,fa,58,98,e7,bb,8c,ba,bc,ec,95,\
"rkeysecu"=hex:0a,98,7a,e1,74,98,08,d0,1e,71,33,6c,33,b8,0d,12
.
--------------------- DLLs chargÈes dans les processus actifs ---------------------
.
- - - - - - - > 'lsass.exe'(704)
c:\program files\Controle Parental\bin\lsp.dll
.
Heure de fin: 2012-01-06 19:39:02
ComboFix-quarantined-files.txt 2012-01-06 18:39
.
Avant-CF: 100†684†177†408 octets libres
AprËs-CF: 106†881†642†496 octets libres
.
- - End Of File - - 8CF1A72458DB9C83DD2EE6C8554CB679